<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Notepad++</title><description>Actively exploited vulnerabilities affecting Notepad++ products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/notepad.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-15556 — Notepad++ Download of Code Without Integrity Check Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-15556</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-15556</guid><description>Notepad++&apos;s built-in WinGUp update mechanism fails to verify the integrity of downloaded update packages. An attacker positioned to intercept or redirect that update traffic — for example, via a network-based man-in-the-middle attack — could substitute a malicious installer, resulting in arbitrary code execution under the victim&apos;s account privileges. Because Notepad++ is widely deployed across enterprise environments, this supply-chain-style attack path poses meaningful risk to large numbers of users.</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate><category>Notepad++</category><category>Notepad++</category></item></channel></rss>